pinecone

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is coherent as a Membrane-based Pinecone wrapper, and the CLI comes from a plausible official npm source, so this is not confirmed malware. However, the skill's real footprint routes Pinecone authentication and data access through Membrane's platform instead of Pinecone's official interfaces, creating a third-party credential/data mediation risk that is larger than the description suggests.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 03:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpinecone%2F@ccfa06c6d159335a8621150434c9d25db3f0c77b